FOXMAN-UN System Overview
FOXMAN-UN Cybersecurity Deployment Guideline
Basic Cybersecurity Considerations
A Formalized Security Model
Security Policies and Principles
Security Services
Network Design
Network Design
Zones
Possible External Communication (including Remote Access)
Network Elements (NE)
Hosts
User accounts
Services
Patches
Host based Firewall
Physical access / device lock down
BIOS/UEFI and boot configuration
Appropriate use banners
Backup / Recovery
Anti Malware
User Groups
File System
Network shares
Applications / Services
Physical Security
Documentation
Product Related Details
LINUX Security Recommendation
BIOS/UEFI and Bootloader Passwords
Enable SELinux
Require Authentication for Single User
Disable Interactive Boot
OS Patch Management
Removing Unused Programs
Virus Scanner
Enforcing Read-only Mounting of Removable Media
Configurable Logon/Warning Banner
Password Security
Administrative Controls
Insecure Services
Firewall (Ports and Services)
Logging and Auditing
Windows® Security Recommendation
BIOS/UEFI Settings
Data Execution Prevention (DEP)
Removing Unused Programs
Windows® Updates/Patch Management
Virus Scanner
Disabling Devices
Configurable Logon/Warning Banner
User Account Control (UAC)
Create Unprivileged User Account
Firewall (Ports and Services)
Product User Accounts
RADIUS Configuration
Installing a Redundant Network Management System
Verify Authenticity of Obtained SW Distribution
Decommissioning
Reporting a Cybersecurity Vulnerability or Incident
Annex
FOXMAN-UN System Description
Server Redundancy
FOXMAN-UN Architecture
NEM Core and Database
Agents
Managed Network Elements
FOX61x and FOX51x Families
SNMP Devices
NEM Client (Graphical User Interfaces)
Northbound Interfaces
FOXMAN-UN Key Functionality
Fault Management
Configuration Management
Performance Management, Diagnostics and Status
Security Management
FOXMAN-UN Deployment Scenarios
Single User - Single Workstation
Multi-User - Single / Redundant Workstation with Agent(s)
Regionally Organized O&M with Network Partitioning
FOXMAN-UN in a Multi-Vendor Environment
Simple Network Management Protocol (SNMP) Proxy Agent
Reach Through
The Managed Network Environment
Management Interfaces
In-band Management
FOX51x Management Environment
Management Interfaces
In-band ECC sub-networks for FOX515/FOX512
Mixed Networks and Interworking of ECC & EOC Sub-networks
Out-of-band Router Management Sub-network
“FO” NEs Management Environment
SNMP Management Environment
Management Interface
NEM Graphical User Interface
Host Manager
NEM Desktop
File
Applications
Fault Management
Network
System
Options
Table Filters
Help
NEM Configurator
NE Browser
Standard Procedure
NE Discovery
NEs of Type ‘Foreign Objects’
Security Configuration
Fault Management
NE Configuration Management
Operational Aspects
NEM Network Browser (legacy application)
Maps - Group Maps
Symbols
Cut and Paste
Find Symbol Facility
Alarm Indication
Messages
Sections
Map Background
Security
Fault Management
Configuration Management
Managed Objects
Hardware View NE
Hardware View Unit
Hardware View Subunit
FOX61x Views
NEs of Type Foreign Object
Event List (legacy application)
Security Administration
Role-based Access Control (RBAC)
System Roles
User Defined Roles
Administrators
Network Partitioning
Fault Management
Alarm Handling
Alarm Notification
Main Functions
Alarm Summary
Alarm Status Filter
Alarm Severities
Alarm Customization
Units/Subunits
Severity «Off»
Alarm Flooding Protection
Foreign Object Alarms
Alarm Localization
Alarm List
Alarm Acknowledgment
Alarms Properties
Alarm List Printout
Section Alarms
Alarm Email Notification
Alarm Escalation
Alarm History
History File Cycling
History Data Retrieval
Logbook Function
NE Alarm Synchronization
System NE
Trouble Ticketing
Configuration Management
FOX61x NE Configuration
Configuration Changes
Simultaneous Access
NE Profiles
FOX51x NE Configuration
Configuration Changes
Simultaneous Access
Local Configuration Change
Profiles
Inventory for FOX51x
Network Configuration
Section Definition
End to End Configuration
Configuration Tasks
NE Password Tasks
Profile & CPS Tasks
ESW Management
Performance Management, Diagnostics, and Status
Overview
Health Monitor
Monitoring Session
Section
NE
Performance Management
Recommendation ITU-T G.826
Performance Data Retrieval
Automatic Performance Data Collection
Collection Schedules
Results
Metrics Database
MPLS-TP Diagnostics
TDM Diagnostics
FOX51x Diagnostics
Integrated Testing of Subscriber Lines
Status Monitoring
Signaling Bits
Activation / Deactivation States
Idle / Busy States of POTS Lines
Remote Alarms
Controlled Slip Counts
Network Element Timing Source Status
Synchronization Map
PTP Sync Map
Network Element Synchronization
Ethernet Traffic Protection Maps
Spanning Tree Map
Ethernet Ring Protection Switching (ERPS) Map
Networking Package
Terminology
Functionality
Configuration
Status Indications
Defining End Point of an Application
Manual Circuit Configuration
Automatic Circuit Configuration
Protection
NP Usage
TE Graph
NP Reporting Tool
NP Reporting Tool
Ethernet Networking Package
MPLS-TP Architecture and Operations
ENP Main GUI
Hierarchical QoS
Class Types
VPLS Tab
VPWS Tab
Pseudo Wire Tab
Tunnel Tab
Link Tab
NE Tab
Service Profile Tab
Class Type Tab
Create Service Profile
Create Service
Create Tunnel
Manual Routing
Automatic Routing
Advanced Routing
Working and Protecting LSP
OAM Bidirectional Forwarding Detection (BFD)
Path Protection
Encryption
Attached Pseudo Wire
Tunnel Details
Diagnostic
Circuit Emulation
Teleprotection
Service Supervision and Reporting
Adding Services to Supervision
System Services
Adding Services
Advanced Services
Creating Services
Service Supervision Tools and Options
Service Alarms
Service Reporting
Service Report Manager
Print & Information Export
Table Print /Export
NE Reports
Inventory
Installation, Administration & Help Tools
System Administration
License Information
Managing Authentication Keys
Start/Stop Services
Element Agents
Inventory Information
Database Backup and Restore
Managing Main/Standby Configuration
NEM Help Viewer
Remote Executor
Technical Documentation
FOXMAN-UN Standby & Recovery Concepts
Database Backup
Standby System
Standby Concept for FOXMAN-UN
Cold Standby
Warm Standby
Internal Process Recovery
HW and OS Requirements
RHEL Platform
Microsoft Windows Platform
License Concept
Glossary
FOXMAN-UN Licensing Model
Licensing Model Overview
Main Server & Client
Standby Server
Non-commercial Demo License
Test License (lab use)
Licensing Model Details
NEM Client
Extra Concurrent User
Ethernet Networking Package ENP (MPLS-TP)
Networking Package NP (TDM)
Ethernet Protection Ring (ERPS)
Spanning Tree Protocol (STP)
SNMP Southbound Interface (SBI) Devices
Advanced Service Supervision (>50 services)
System Service Supervision (>50 services)
Service Level Agreement (SLA) Reporting
Northbound Interface (SNMP) Fault Management
FOXMAN-UN Upgrade
Integration of Specific Network Node Types
FOX61x Nodes Integration
FOX660 Nodes Integration (restricted)
XMC20/UMUX Nodes Integration
Basic Package with EDS500 Nodes Integration
EDS500 Nodes SBI Integration
Support Encryption with DIRAC
FOXMAN-UN Logging Feature Description
Introduction
Concept
Log Files
Server Setup
Event Server
System Event Log Manager
Security Event Log Manager
Syslog backend
Syslog Server
Backup/restore interaction
Security Events
Upgrade
Appendix
NEM Client Log Files (/var/log/nem/logclient)
Enable / Disable Program Tracing
Log, Trace and *.txt File Rotation Definitions
Upgrading FOXMAN-UN and FOX61x - Application Note
Symbols and Notations
Target Audience
Terms and Abbreviations
Purpose and Scope
Supported Upgrade Scenario
Foreign Object (FO) Upgrade
FOX61x Upgrade
Upgrade Sequences
Network Upgrade Sequence without MPLS-TP Encryption
Network Upgrade Sequence with MPLS-TP Encryption
Network Upgrade Sequence without Network Manager
Workaround for FOXMAN-UN Upgrade in Main/Standby Setup
Unsupported Upgrade Scenarios
FOX61x Upgrade
Version Information
Background Information
Upgrade R17A to R18
FOXMAN-UN and DIRAC upgrade
Upgrade FOXMAN-UN database from R17A to R18
Post-upgrade steps
FOX61x upgrade
Pre-upgrade steps
Upgrade via FOXMAN-UN (ESW Distribution Wizard)
Upgrade via FOXCST
Unit ESW has System Release R17A Status
Management Connection to the Active Core Unit
Equipment is Fault Free
Correct FOXCST Version is being used
Limitations for the Upgrade
Step-by-Step Procedure
Post-upgrade steps
Upgrade R16B to R18
FOXMAN-UN and DIRAC upgrade
Upgrade FOXMAN-UN database from R16B to R18
Post-upgrade steps
FOX61x upgrade
Pre-upgrade steps
Upgrade via FOXMAN-UN
Upgrade via FOXCST
Unit ESW has System Release R16B Status
Management Connection to the Active Core Unit
Equipment is Fault Free
Correct FOXCST Version is being used
Limitations for the Upgrade
Step-by-Step Procedure
Post-upgrade steps
SENC1 Software upgrade to R18
Foreign Object (FO) Upgrade to R18